T09 · Insecure Skill Coding Practices
- Location
scripts/shared/storage/keys.js:44- Finding
Private keys are stored in plaintext by default without enforced restrictive file permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This identity skill is mostly coherent, but it handles long-lived private keys with unsafe defaults that users should review before installing.
Review this before installing if the agent identity will matter outside a test environment. Set BILLIONS_NETWORK_MASTER_KMS_KEY before creating identities, avoid passing private keys on the command line, restrict access to $HOME/.openclaw/billions, rotate any keys previously stored in plaintext, and treat signed tokens/challenges as sensitive because challenge replay protection is weak.
scripts/shared/storage/keys.js:44Private keys are stored in plaintext by default without enforced restrictive file permissions
scripts/verifySignature.js:19Authentication challenges can be replayed because they neither expire nor get consumed
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `identities.json` | Identity metadata |
| `defaultDid.json` | Active DID and associated public key |
| `challenges.json` | Per-DID challenge history |
| `credentials.json` | Verifiable credentials |
There are several ways of storing private keys, to enable master key encryption as described in the **KMS Encryption** section below.
The declared description suggests a full decentralized identity integration centered on Billions, ERC-8004, attestation registries, and iden3-based authentication proof workflows. The actual code chunk only retrieves and displays existing identities from storage. That is identity-related, but it does not implement the key described capabilities or primary purpose. This is a material description-behavior mismatch rather than a mere supporting utility detail, because the code's concrete function is a simple identity listing script rather than proof generation/verification or agent-human identity linking.
The declared description presents a blockchain/decentralized identity skill centered on agent-human identity linking, attestation registries, and authentication proof workflows. The supplied code chunk only provides generic local file storage for identity objects. It does not interact with blockchain registries, ERC-8004, iden3 protocols, authentication proofs, or any network/external identity systems. While file storage could be a supporting implementation detail within a larger identity system, this chunk by itself does not accurately represent the declared purpose and instead has a much narrower, materially different behavior.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.
cd scripts && npm inst
The skill documents the location and contents of highly sensitive files, including kms.json containing private keys and credentials.json containing verifiable credentials, and notes that keys may be stored in plaintext when an environment variable is not set. In an agent setting, a skill centered on identity management and local credential storage is inherently high risk because any overbroad file access, logging, or prompt-driven exfiltration could expose long-lived secrets and identity artifacts.
- `kms.json` - **CRITICAL**: Contains private keys (encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY is set, otherwise in plaintext)
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data
ws 8.18.0 is present and carries advisories for memory disclosure and memory-exhaustion denial of service. In an agent identity skill that may maintain network/WebSocket connections to blockchain or verifier services, a vulnerable WebSocket stack meaningfully increases exposure to remote attacks and service instability.
brace-expansion 2.0.2 is present and has multiple denial-of-service advisories related to pathological expansion behavior. This is a real vulnerable package in the dependency tree, but in this context it is likely only reachable through tooling or ancillary parsing paths rather than core runtime identity verification logic.
fast-uri 3.1.0 is present with multiple host confusion and SSRF-related advisories. In an identity skill that may fetch DIDs, JSON-LD contexts, attestation registries, or verifier endpoints, malformed URL parsing can materially increase risk by misrouting requests or enabling SSRF against internal services.
ws 7.5.10 is flagged for memory exhaustion DoS and is present in the dependency graph. If reachable through RPC/WebSocket features used by blockchain integrations, a remote peer could degrade or crash the process through crafted fragmented traffic.
underscore 1.13.6 is flagged for unlimited recursion in _.flatten and _.isEqual, enabling potential DoS on crafted nested data. In an identity/proof-processing ecosystem that may compare or flatten attacker-supplied JSON-like objects, this can become practically relevant even if the vulnerable functions are only used transitively.
undici 5.29.0 is present with numerous advisories including request smuggling, queue poisoning, and header injection classes of issues. This is especially concerning for an identity-verification skill that likely performs outbound HTTP to registries, issuers, DID resolvers, or JSON-LD resources, because network-layer confusion could undermine integrity, confidentiality, or availability.
ws 8.17.1 is present and affected by memory disclosure and memory exhaustion advisories. Given the presence of blockchain and RPC-related libraries, this WebSocket issue is credibly reachable in real deployments and could expose process memory or cause denial of service from remote peers.
The bootstrap code stores credential data in a local file named credentials.json alongside identity-related artifacts, and the same module also initializes file-backed key storage. In an agent identity context, these files may contain highly sensitive credentials or metadata; if stored unencrypted or with broad filesystem permissions, local compromise, backup leakage, or multi-user host access could expose identities and enable impersonation or correlation.
function newDataStorage(ethStateStorage) {
return {
credential: new CredentialStorage(
new IdentitiesFileStorage("credentials.json"),
),
identity: new IdentityStorage(
new IdentitiesFileStorage("identities.json"),
When no master key is present, _encodeEntry stores privateKeyHex directly on disk under provider: "plain", meaning highly sensitive secret material is persisted unencrypted. In an agent identity system, compromise of the host, backups, logs, or filesystem access can immediately yield signing keys and allow impersonation, fraudulent attestations, or long-term identity takeover.
The README instructs users to run npx clawhub@latest install verified-agent-identity, which pulls and executes the latest package version at install time rather than a fixed, reviewed version. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute attacker-controlled code during installation.
The suggested phrase Please link your agent identity to me. is a natural-language trigger that could overlap with ordinary conversation and cause the skill to initiate a sensitive identity-linking workflow unintentionally. In an agent environment, ambiguous triggers are risky because another user, prompt injection, or surrounding context could activate identity operations without the operator clearly intending that exact action.
The human installation step again uses npx clawhub@latest, causing execution of whatever code is current in the registry at the time of install. Because npx executes fetched packages, this is a real supply-chain exposure rather than a documentation-only concern.
The skill advertises and instructs use of Node-based scripts that access local sensitive files under $HOME and interact with external identity/network systems, yet it declares no explicit tool scope or permission boundaries. In an agent environment, missing scope makes it easier for the skill to be invoked with broader-than-necessary filesystem, environment, or network access, increasing the blast radius of misuse or compromise.
The skill explicitly instructs users to supply a raw private key via a command-line flag. Command-line arguments are commonly exposed through shell history, process listings, logs, telemetry, and agent traces, which can leak the key and fully compromise the associated identity.
This code accepts a user-supplied private key or generates a new one, then derives a signer from it, but there is no confirmation prompt, user-facing warning, or explanatory message about handling sensitive credential material. Because private keys are highly sensitive, users should be clearly informed when the skill consumes or generates them.
The code initializes file-backed storage for KMS keys and later stores credentials, identities, DIDs, and challenges in JSON files. While comments describe the components, there is no confirmation prompt, user-facing log, or explicit warning that sensitive wallet material and identity data will be persisted locally.
This file configures external endpoints for the Billions Network RPC and a revocation service, and uses them to create state and credential status resolvers. Although the code comments describe the configuration, there is no visible user-facing notice that runtime data may be transmitted to external services.
The list() method returns every stored private key in raw form, greatly expanding exposure beyond what a normal key-management interface should provide. Any caller with access to this method can enumerate and exfiltrate all key material at once, which is especially risky in an identity/authentication skill where private keys represent agent identity and signing authority.
The verification flow hard-codes user-facing prompts such as "Please provide your DID to start verification" and "Please sign this challenge" without offering any language or locale choice. This can violate language/locale policy when a skill forces a specific language without user opt-in.
The script creates a wallet connected to a JSON-RPC provider using the configured mainnet URL, which causes interaction with an external network service. There is no visible user-facing notice in this file that blockchain RPC communication will occur or that related metadata may be transmitted.
No suspicious patterns detected.